HackingCustomer Data InvolvedPIIPHIIDENTITY_BASICLowContained
ANNE ARUNDEL DERMATOLOGY MANAGEMENT, LLC
bd_8696e51394d3f84a · schema v1 · pii pii-v1
Full breach record for ANNE ARUNDEL DERMATOLOGY MANAGEMENT, LLC →Anne Arundel Dermatology notified consumers of a data breach where an unauthorized third party accessed systems containing personal and health information between Feb 14 and May 13, 2025. The incident was discovered on May 20, 2025. The company engaged third-party experts, implemented additional security measures, and offered 24 months of identity theft protection services. No misuse was confirmed at the time of notice.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2711035b7209e269Montana State AGfiled 2025-07-11Candidate
- bd_32e2060a3205fc73California State AGfiled 2025-07-11Verified
- bd_953114c4c8d6d4feTexas State AGfiled 2025-07-11Verified
- bd_fbd042e2d3263799Delaware State AGfiled 2025-07-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-07-11-anne-arundel-dermatology-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 11, 2025
- Raw hash
- 35ebe433cc206c2fc607b719af8bf30681cc63a0020143aa83fc6aebeb18eb93
Reporting entity
- Name
- ANNE ARUNDEL DERMATOLOGY MANAGEMENT, LLCnorm: anne arundel dermatology management
Victim entity
- Name
- ANNE ARUNDEL DERMATOLOGY MANAGEMENT, LLCnorm: anne arundel dermatology management
Incident
- Discovered
- May 20, 2025
- Materiality determined
- —
- Notification sent
- Jul 11, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.